chromeÔÚҰʹÓÃ0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-07

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5786£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º 

Google Chrome < 72.0.3626.121


Îó²î¸ÅÊö


Google ChromeÊÇÒ»¿îWebä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£FileReaderÊÇÆäÖеÄÒ»¸öÎļþ¶ÁÈ¡²å¼þ¡£¡£¡£¡£¡£¡£


¸ÃÎó²îÓ°ÏìËùÓвÙ×÷ϵͳÉϵÄChrome Èí¼þ£¬£¬£¬ £¬£¬£¬°üÀ¨Î¢Èí Windows¡¢Æ»¹û macOS ºÍ Linux ϵͳ¡£¡£¡£¡£¡£¡£


¸üÈÃÈ˵£ÐĵÄÊÇ£¬£¬£¬ £¬£¬£¬¹È¸èÖÒÑÔ³ÆÕâ¸ö0day RCEÎó²îÒÑÔâʹÓᣡ£¡£¡£¡£¡£


Google Chrome 72.0.3626.121֮ǰ°æ±¾£¬£¬£¬ £¬£¬£¬FileReaderµÄʵÏÖÖб£´æÊͷźóÖØÓÃÎó²î¡£¡£¡£¡£¡£¡£Õâ¸öʹÓúóÊÍ·ÅÎó²îÊÇÒ»ÀàÄÚ´æËð»µbug£¬£¬£¬ £¬£¬£¬ÔÊÐíË𻵻òÐÞ¸ÄÄÚ´æÖеÄÊý¾Ý£¬£¬£¬ £¬£¬£¬Ê¹µÃµÍȨÏÞÓû§Äܹ»ÔÚÊÜÓ°ÏìµÄϵͳ»òÈí¼þÉÏÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£Ëü¿Éµ¼ÖµÍȨÏÞ¹¥»÷Õß»ñÈ¡ Chrome web ä¯ÀÀÆ÷ÉϵÄȨÏÞ£¬£¬£¬ £¬£¬£¬ÌÓÒÝɳÏä±£»£»£»£»¤²¢ÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


ҪʹÓøÃÎó²î£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßËùÐèµÄÖ»ÊÇÓÕÆ­Êܺ¦Õß·­¿ª¡¢»òÕß½«ËüÃÇÖØ¶¨ÏòÖÁÒ»¸öÌØÊâ½á¹¹µÄÍøÒ³£¬£¬£¬ £¬£¬£¬¶øÎÞÐèÈκνøÒ»²½µÄ½»»¥¡£¡£¡£¡£¡£¡£


¸ÃÎó²îÓÉGoogle's Threat Analysis GroupµÄClement LecigneÓÚ2019-02-27±¨¸æ£¬£¬£¬ £¬£¬£¬ÏÖÔÚûÓÐÐû²¼ÆäËüϸ½Ú¡£¡£¡£¡£¡£¡£


½ÏÁ¿Á½¸ö°æ±¾µÄÔ´´úÂ룬£¬£¬ £¬£¬£¬·¢Ã÷third_party/blink/renderer/core/fileapi/file_reader_loader.ccÓÐһЩ¸Ä¶¯¡£¡£¡£¡£¡£¡£ÔÚ·µ»Ø²¿·ÖЧ¹ûʱ¸´ÖÆArrayBufferÒÔ×èÖ¹¶Ôͳһ¸öµ×²ãArrayBufferµÄ¶à¸öÒýÓᣡ£¡£¡£¡£¡£


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



ÐÞ¸´½¨Òé



ʹÓÃchromeä¯ÀÀÆ÷µÄÓû§Çë·­¿ªchrome://settings/helpÒ³ÃæÉó²éÄ¿½ñä¯ÀÀÆ÷°æ±¾£¬£¬£¬ £¬£¬£¬ÈôÊDz»ÊÇ×îаæ(72.0.3626.121)»á×Ô¶¯¼ì²éÉý¼¶£¬£¬£¬ £¬£¬£¬ÖØÆôÖ®ºó¼´¿É¸üе½×îа档¡£¡£¡£¡£¡£


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


²Î¿¼Á´½Ó


https://thehackernews.com/2019/03/update-google-chrome-hack.html

https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html

https://chromium.googlesource.com/chromium/src/+/150407e8d3610ff25a45c7c46877333c4425f062%5E%21/#F0